pup: remove obs-pipelines from OAuth excluded endpoints (cleanup) - #755
Merged
platinummonkey merged 4 commits intoAug 25, 2026
Merged
Conversation
Remove 6 obs-pipelines endpoints from OAUTH_EXCLUDED_ENDPOINTS so raw_get/raw_post send the OAuth bearer token. The server already accepts OAuth on all v2 obs-pipelines routes.
srosenthal-dd
marked this pull request as ready for review
August 25, 2026 15:22
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b141caf5ac
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
srosenthal-dd
marked this pull request as draft
August 25, 2026 15:31
Add two tests verifying that obs-pipelines routes no longer require API-key fallback after removal from OAUTH_EXCLUDED_ENDPOINTS: - test_no_fallback_for_obs_pipelines: asserts requires_api_key_fallback returns false for all formerly-excluded method/path combinations (collection, ID-parameterized, validation), plus a non-matching method - test_raw_get_obs_pipelines_uses_oauth_bearer: end-to-end test that raw_get sends the Authorization: Bearer header and omits DD-API-KEY for an obs-pipelines pipeline path
This comment has been minimized.
This comment has been minimized.
The count test is prone to merge conflicts and tests no actual behavior. The per-group fallback tests provide real coverage.
platinummonkey
previously approved these changes
Aug 25, 2026
srosenthal-dd
marked this pull request as ready for review
August 25, 2026 19:48
platinummonkey
approved these changes
Aug 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Remove 6 obs-pipelines entries from
OAUTH_EXCLUDED_ENDPOINTSso thatraw_get/raw_postcalls to obs-pipelines paths send the OAuth bearer token.The
pup obs-pipelines diffcommand usesraw_client::raw_get(not the typed SDKmake_api!path used by the other 5 obs-pipelines commands). Because the obs-pipelines entries were inOAUTH_EXCLUDED_ENDPOINTS,apply_authfell back to API-key-only auth, makingpup obs-pipelines diffunusable on an OAuth-only session -- even though the server already accepts OAuth on the underlying route. Removing these entries fixes that.The other 5 obs-pipelines commands (list, get, create, update, delete, validate) already support OAuth via
make_api!and are unaffected by this change.No server-side dependency -- the server already accepts OAuth on all v2 obs-pipelines routes.
Changes
src/raw_client.rs: Removed 6 obs-pipelines entries fromOAUTH_EXCLUDED_ENDPOINTS(46 -> 40), updated count test